Published Security3 min read
One AWS key, 87 minutes, 1,500 charities: encryption at rest did nothing
Beacon says an access key was potentially exposed in public JavaScript build artifacts, and the attacker downloaded the whole CRM. Valid credentials meant AWS decrypted on the way out.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- A compromised AWS access key was the likely root cause of the cyber-attack on CRM provider Beacon, which exposed personal information held by around 1,500 UK charities.
- Beacon said in an August 12 incident update that the access key was potentially exposed in public JavaScript build artifacts, suggesting an error was made in the course of software development.
- Beacon assessed that the attacker used the valid credentials to access and download all data contained within the CRM platform, including attachment files, impacting its entire 1,500-strong customer base of charitable organisations.
- The affected data includes personal information held by charities operating in highly sensitive areas such as healthcare and victim support.
- While the data was encrypted at rest in AWS, the threat actor's valid credentials meant its downloads would have been decrypted by AWS and available in readable form.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A single AWS access key, potentially exposed in public JavaScript build artifacts, is the likely root cause of the attack on CRM provider Beacon that has exposed personal information held by around 1,500 UK charities [1][2]. Beacon has assessed that the attacker used those valid credentials to download all data in the platform, including attachment files, and that the download took about 87 minutes [3][6][1].
The mechanics are unremarkable, which is the point. Beacon said in an August 12 incident update that the key was potentially exposed in public JavaScript build artifacts, which points to an error made during software development rather than an intrusion chain [2]. After that there was nothing to intrude on. The credentials were legitimate, so the platform did what it was built to do. Beacon notes the data was encrypted at rest in AWS, but says the attacker's valid credentials meant the downloads would have been decrypted by AWS and available in readable form [5]. Encryption at rest defends against someone removing the storage, not against someone holding the key and asking.
The timeline came out of billing data. Analysis of Beacon's AWS Cost and Usage reports put the start of malicious activity at 01:20:16 UTC on July 27, lasting approximately one hour and 27 minutes [6], which places the end around 02:47 UTC [2]. That window correlates with a significant increase in data downloads across July 27 and 28 [7]. Fifteen hundred customer datasets in 87 minutes is roughly 17 a minute [3]. Anyone whose exfiltration model is measured in days should revise it.
What went out: supporters' names, email addresses, telephone numbers and donation records, which Infosecurity Magazine notes could support social engineering against individual victims [14]. Beacon says the compromised system did not hold sensitive patient information, payment card details or bank account information [15]. That boundary matters less than it reads, because the customer base includes charities operating in healthcare and victim support [4]. The Survivor's Trust, which provides specialist rape and sexual abuse support services, is a confirmed victim and has urged its supporters to stay alert to scams in the coming weeks [12][13]. A name, a phone number and a donation history at a charity that implies who you are is a working pretext.
Beacon says it has not detected any attempts by the attacker to maintain persistence in its environment, and has reset all credentials for services and accounts integrated with AWS [8][9]. It also says there is no indication so far that the stolen data has been published online or otherwise misused [10]. That is consistent with a single pass whose value is realised later, elsewhere.
On liability, the regulator has already moved on one case. The Survivor's Trust said on August 13 that the Information Commissioner's Office had reviewed its case and concluded the charity holds no responsibility for the breach [12]. All of Beacon's charity customers have been advised to report the breach to the ICO themselves [11]. At least eight have gone public, including Shrewsbury and Telford Hospital Charity, the British Deaf Association, Yorkshire's Brain Tumour Charity, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, the Clock Tower Sanctuary and Victim Support [16][4].
Three things to watch. Whether the ICO's no-responsibility finding extends to the remaining roughly 1,499 customers, each of which is a controller filing its own report [12][11][5]. Whether Beacon publishes how a live key reached a public build artifact, and what in its pipeline was supposed to catch it [2]. And whether the current absence of published data holds, given that donation records plus contact details are more useful quietly than loudly [10][14].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A compromised AWS access key was the likely root cause of the cyber-attack on CRM provider Beacon, which exposed personal information held by around 1,500 UK charities.
- [2]
Beacon said in an August 12 incident update that the access key was potentially exposed in public JavaScript build artifacts, suggesting an error was made in the course of software development.
- [3]
Beacon assessed that the attacker used the valid credentials to access and download all data contained within the CRM platform, including attachment files, impacting its entire 1,500-strong customer base of charitable organisations.
- [4]
The affected data includes personal information held by charities operating in highly sensitive areas such as healthcare and victim support.
ReportedView cited source - [5]
While the data was encrypted at rest in AWS, the threat actor's valid credentials meant its downloads would have been decrypted by AWS and available in readable form.
- [6]
Analysis of Beacon's AWS Cost & Usage reports identified that malicious activity began on July 27 at 01:20:16 UTC and lasted for approximately one hour and 27 minutes.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- infosecurity-magazine.comAug 13Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities
Additional citations
- Infosecurity Magazine, reporting Beacon
- Beacon incident update, August 12
- Beacon
- The Survivor's Trust statement, August 13
- Infosecurity Magazine



